Microsoft · Windows Print Spooler · CVE-2021-34527
**Name of the Vulnerable Software and Affected Versions**
Windows Print Spooler (affected versions not specified)
**Description**
A remote code execution flaw exists in the Windows Print Spooler service due to improper privileged file operations and access control deficiencies. An attacker with low privileges can execute arbitrary code with SYSTEM privileges by spoofing print jobs or loading a malicious DLL library. Successful exploitation allows the attacker to install programs, view, modify, or delete data, and create new accounts with full user rights. This issue has been utilized in ransomware attacks.
**Recommendations**
Disable the Print Spooler service on non-print servers.
Enforce the use of signed drivers.
Monitor Active Directory for suspicious activity.